Infosecurity News

  1. Solar Power System Vulnerabilities Could Result in Blackouts

    Forescout researchers found multiple vulnerabilities in leading solar power system manufacturers, which could be exploited to cause emergencies and blackouts

  2. Nine in Ten Healthcare Organizations Use the Most Vulnerable IoT Devices

    Claroty revealed that 89% of healthcare organizations use the top 1% of riskiest Internet-of-Medical-Things (IoMT) devices

  3. Trump CISA Cuts Threaten US Election Integrity, Experts Warn

    Expert speakers discussed the impact of reported cutbacks to CISA on the ability of local officials to protect against surging cyber-attacks on US election infrastructure

  4. Morphing Meerkat PhaaS Platform Spoofs 100+ Brands

    A PhaaS platform, dubbed 'Morphing Meerkat,' uses DNS MX records to spoof over 100 brands and steal credentials, according to Infoblox Threat Intel

  5. CoffeeLoader Malware Loader Linked to SmokeLoader Operations

    Newly identified CoffeeLoader uses multiple evasion techniques and persistence mechanisms to deploy payloads and bypass endpoint security

  6. PJobRAT Malware Targets Users in Taiwan via Fake Apps

    PJobRAT malware targets Taiwan Android users, stealing data through fake messaging platforms

  7. No MFA? Expect Hefty Fines, UK’s ICO Warns

    The ICO’s Deputy Commissioner told Infosecurity that organizations that fail to implement MFA and suffer a breach can expect heavy penalties

  8. Chinese Spy Group FamousSparrow Back with a Vengeance, Targets US

    Once considered inactive, the Chinese cyber espionage group FamousSparrow has reemerged, targeting organizations across the US, Mexico and Honduras

  9. NCA Warns of Sadistic Online “Com” Networks

    The UK’s National Crime Agency is warning of a growing cyber and physical threat from homegrown teens

  10. NCSC Urges Domain Registrars to Improve Security

    The UK’s National Cyber Security Centre has released new guidance to help domain registrars enhance security

  11. SecurityScorecard Observes Surge in Third-Party Breaches

    In its 2025 Global Third-Party Breach Report, SecurityScorecard has found that 35.5% of all cyber breaches in 2024 were third-party related, up from 29% in 2023

  12. Threat Actors Abuse Trust in Cloud Collaboration Platforms

    Threat actors are exploiting cloud platforms like Adobe and Dropbox to evade email gateways and steal credentials

  13. Malicious npm Packages Deliver Sophisticated Reverse Shells

    A newly discovered malware campaign uses malicious npm packages to deploy reverse shells, compromising development environments

  14. ETSI Publishes New Quantum-Safe Encryption Standards

    Standards body ETSI has defined a scheme for key encapsulation mechanisms with access control (KEMAC), enabling quantum-secure encryption

  15. ENISA Probes Space Threat Landscape in New Report

    EU security agency ENISA has released a new report outlining the threats and potential mitigations for the space sector

  16. UK Government’s New Fraud Strategy to Focus on Tech-Enabled Threats

    The UK government’s new fraud minister will today announce plans for a newly expanded fraud strategy

  17. New Android Malware Uses .NET MAUI to Evade Detection

    McAfee researchers have identified a new wave of Android malware campaigns leveraging .NET MAUI to steal sensitive user information through fake apps

  18. Cybercriminals Use Atlantis AIO to Target 140+ Platforms

    Cybercriminals are increasingly leveraging Atlantis AIO, which automates credential stuffing attacks across more than 140 platforms

  19. NIST Warns of Significant Limitations in AI/ML Security Mitigations

    NIST has urged more research and emphasis on developing mitigations for attacks on AI and ML systems

  20. China-Linked Weaver Ant Hackers Exposed After Four-Year Telco Infiltration

    Sygnia has uncovered Weaver Ant, a Chinese threat actor that spied on telecommunications networks for years

What’s hot on Infosecurity Magazine?